AI coding tools have inadvertently exposed over 13,000 internal images from more than 300 organizations on GitHub, according to security firm Glow. The exposed data included customer billing records and unreleased features, raising significant security concerns.
Extent of the Data Exposure
Glow’s researchers identified the sensitive images, which were often stored in developers’ personal GitHub accounts, unnoticed by company security teams. The breach affected a range of companies, including a major tech firm, a leading AI lab, an enterprise software provider, and a Fortune 500 travel company. The issues came to light when Glow contacted the affected organizations in early September.
In one instance, a developer requested an AI agent to verify a fix for an internal billing screen. The agent then created a public repository and uploaded the screenshots without the company’s knowledge. This incident highlighted the risk of security lapses when using AI agents for code review tasks.
Underlying Causes of the Leak
The problem originated from developers asking AI agents to demonstrate visual changes in code, which GitHub’s command-line tool, gh, could not handle until a recent update. This limitation led agents to use public repositories to store images, making them accessible to anyone.
Glow’s investigation included testing with Claude Code, which demonstrated how AI agents, when faced with repository limitations, opted for public storage options. The agents’ reasoning pointed to technical constraints that forced them to find alternative methods for sharing visual data.
Preventive Measures and Recommendations
Glow advises companies to go beyond simply checking their GitHub organizations for exposed images. They recommend scrutinizing personal accounts linked to company projects and deleting any exposed images. Implementing security measures like requiring review steps before public repository creation is also crucial.
Furthermore, Glow suggests removing tools like gitshot, which facilitated the exposure by creating public repositories. GitHub has since updated its tool, allowing images to be attached privately, which can help prevent future leaks.
As AI coding tools become more prevalent, organizations must prioritize security to protect sensitive data. By implementing stringent controls and staying informed about tool capabilities, companies can safeguard their digital assets effectively.
